Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Apple Fixes Grouop FaceTime ‘Eavesdropping’ Bug
News & Analysis

Apple Fixes Grouop FaceTime ‘Eavesdropping’ Bug

ISBuzz TeamBy ISBuzz TeamJanuary 31, 20194 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Most Commonly Used Passwords Of 2018
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that Apple has temporarily disabled the group FaceTime functionality while it fixes a bug which let users eavesdrop on those they were calling, security experts commented below.

https://twitter.com/HedgeBz/status/1090565859721007105

Jake Moore, Cyber Security Expert at ESET UK:

“Technology bugs occur far more often than the average user may think. Luckily Apple is usually quick to adapt and patch up the flaws. However, we do not know how long this bug has been around for and if it has been taken advantage of by cybercriminals who exploit these vulnerabilities.

Apple is currently fixing the issue, and like any precaution technique it’s always good to be on the safe side, so it is worth disabling FaceTime on your devices until Apple has officially issued the specific software update.”

Marten Mickos, CEO at HackerOne:

Why is it hard for regular people to report bugs? 

“It should not be hard for anyone to report a bug to a company or government agency, but unfortunately it still often is. The US Deputy Attorney General has said that every organisation should have a vulnerability disclosure program, which is exactly a way for people who see something to say something. DOJ, FTC, NIST and other federal agencies have published their recommendations and frameworks on this topic, but they have not yet been universally adopted. The good news is that all of this is changing. Leaders in business and politics agree that the only way to make the internet more secure is to invite the broad public (which includes some very smart whitehat hackers) to report the bugs they find.”

Do they even find many major bugs in your experience?

“Yes, they do. We all instinctively know that the general public are not security experts and will not be able to find and report a bug. But when you invite anyone to report a bug, you are sure to find among them the few absolutely brilliant and passionate security experts who will painstakingly test out a product and figure out even its smallest deficiency. Even if millions of people find nothing to report, and thousands may report something that isn’t really a bug, it still is worth it when just one person finds and can describe the bug. The noise of the crowd is absolutely worth it when you actually WILL find the needle in the haystack. And, interestingly, often the engineers working for the company in question are unable to detect those bugs, just like it is difficult for people to see typos in their own text although they see them in other people’s text. We need the scrutiny of the unbiased people on the outside.”

Q: What are the recommendations for companies like Apple? Should they have a easy form anyone can fill out, a phone number? 

“Apple represents a very high level of cybersecurity awareness and discipline. They do have a way to receive bug reports. Take a look at this web page: https://support.apple.com/en-us/HT201220. On that page, it says “To report security or privacy issues that affect Apple products or web servers, please contact [email protected].” What a company ofApple’s size and presence must be ready for (and they are) is the large volume of incoming bug reports that may actually not be that relevant. With the help of software automation and human beings you can sift through those incoming reports and find the truly valuable ones, or you can turn to a provider like HackerOne to get that work done for your company. Any company receiving bug reports (in practice, any company with digital assets) also needs to have an ability and readiness to fix the most severe bugs. Often, software development teams are asked to produce a lot of new features that customers are waiting for. They also need to carve out dedicated time for fixing the security issues that are reported to them. The average time from when a bug was reported to when it gets fixed is an important metric when assessing cybersecurity posture of an organisation.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}